VMTech
Discuss a project

Fake macOS updates spread DPRK-linked wallet stealer through sponsored search

Fake macOS updates spread DPRK-linked wallet stealer through sponsored search

On July 30, 2026, AllSecure detailed a DPRK-linked macOS malvertising campaign in the Contagious Interview cluster, also tracked as UNC5342. A sponsored search result opened a fake full-screen system update and ultimately delivered an infostealer targeting 157 cryptocurrency wallets plus a malicious Chrome extension.

Why ordinary browsing now carries risk

The observed victim was searching for electrophoresis machines and clicked a sponsored result for an apparent supplier. The page immediately simulated a macOS reboot, copied a command to the clipboard and instructed the user to paste it into Terminal. Attempts to repeat the sequence failed, suggesting single-use activation.

This ClickFix method turns panic into user-authorised execution. The wider risk landscape already includes JINX-0164 attacks on crypto firms through fake recruiters, while this campaign extends similar social engineering beyond recruitment and coding tests into routine product research.

How the attack chain works

The pasted curl command retrieves a Node.js backdoor that establishes persistence through LaunchAgent. Every five minutes, the implant contacts its C2 infrastructure and executes JavaScript returned by the server. It obtains the live server address from an Ethereum smart contract, making infrastructure disruption harder.

The first additional payload collects data from Chrome, Brave, Edge, Firefox, Opera and Vivaldi, alongside SSH, AWS, Azure and npm keys. The second is a sideloaded extension named Google Drive Offline, installed by modifying Chrome’s Secure Preferences file and designed to drain wallets.

Two embedded Ethereum addresses provide C2 configuration. Each contract was created through the same sequence: fund a disposable wallet with about 0.0126 ETH, deploy and configure the contract, forward roughly 0.006 ETH left over, then abandon the wallet. Funding links also connect the backdoor and extension to one actor.

“The pattern suggests an operator that has industrialised deployment: fund, deploy, configure, drain leftovers, abandon, repeat.” — AllSecure

For businesses, sponsored search results can no longer be treated as inherently safer than unsolicited messages. Controls should restrict unapproved Terminal commands, flag LaunchAgent changes and browser-extension sideloading, and protect cryptocurrency and cloud credentials with isolation and least privilege.

#macos#cybersecurity#malware#cryptosecurity#threatintelligence
Open analytics
On the site 0 views
min read 3 31.07.2026
Instagram

Fake macOS updates spread DPRK-linked wallet stealer through sponsored search

Open the post on Instagram ↗